CVE-2024-27048
In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: handle pmk_op allocation failure The kzalloc() in brcmf_pmksa_v3_op() will return null if the physical memory has run out.
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: handle pmk_op allocation failure The kzalloc() in brcmf_pmksa_v3_op() will return null if the physical memory has run out. As a result, if we dereference the null value, the null pointer dereference bug will happen. Return -ENOMEM from brcmf_pmksa_v3_op() if kzalloc() fails for pmk_op.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.27% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/6138a82f3bccfc67ed7ac059493579fc326c02e5Patch
- https://git.kernel.org/stable/c/9975908315c13bae2f2ed5ba92870fa935180b0ePatch
- https://git.kernel.org/stable/c/b4152222e04cb8afeeca239c90e3fcaf4c553b42Patch
- https://git.kernel.org/stable/c/df62e22c2e27420e8990a4f09e30d7bf56c2036fPatch
- https://git.kernel.org/stable/c/6138a82f3bccfc67ed7ac059493579fc326c02e5Patch
- https://git.kernel.org/stable/c/9975908315c13bae2f2ed5ba92870fa935180b0ePatch
- https://git.kernel.org/stable/c/b4152222e04cb8afeeca239c90e3fcaf4c553b42Patch
- https://git.kernel.org/stable/c/df62e22c2e27420e8990a4f09e30d7bf56c2036fPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.